Storage limitation, or keeping data for no longer than necessary, is a key part of GDPR compliance. The GDPR consists of several fundamental principles that organisations and individuals must abide by to ensure the lawful and ethical processing of personal data. In this article, we will delve into this principle, exploring its significance, the obligations it imposes, and how it affects data handling practices.
What Does The GDPR Say?
Article 5(e) of the GDPR (brought into UK law by the Data Protection Act 2018) says that “data shall kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals (‘storage limitation’).”
What Does This Mean?
The fifth data protection principle within the GDPR is a pillar of responsible data management. It emphasises that personal data should not be stored for longer than is necessary for the purpose for which it was collected. In short it means:
-
you must understand what you need personal data for
-
decide when this processing activity is due to end
-
you must have arrangements for the deletion of personal data when it is no longer needed
To grasp its significance, let’s break it down:
Defining Storage Limitation
The principle of storage limitation aims to prevent the indefinite retention of personal data. Organisations must establish clear criteria for determining how long data is kept, and this period should align with the intended purpose for which the data was collected.
That means defining retention periods for different categories of personal data and different processing activities. These might include:
-
marketing to potential customers
-
employment, such as recruitment or payroll
-
delivering products and services to existing customers
Archiving Purposes and Research
As the text of the GDPR notes personal data may be retained in identifiable form for archiving purposes and for research. However, appropriate steps have to be taken to ensure people’s “rights and freedoms” are protected. That means at a minimum having the right levels of security and access restriction to prevent a data breach.
You must have a clear purpose in mind if you archive personal data. Don’t keep it “just in case”. You also need to be clear about why anonymised or pseudonymised data would not meet your needs. Finally, you cannot reuse data retained for research purposes for anything else.
Aligning Storage Limitation with Data Minimisation
Storage limitation is closely tied to the third data protection principle, data minimisation. It is much easier to abide by the principle of storage limitation if only the minimum necessary data is collected in the first place. Again, this means understanding what data you need and what you will be processing it for.
-
find out more about the principle of data minimisation here.
The Importance of Storage Limitation
Although it is a statutory requirement to comply with the GDPR, there are wider benefits to getting compliance with the storage limitation principle right.
Safeguarding Individual Privacy
By adhering to storage limitation, organisations respect the privacy of individuals. By ensuring data are not kept indefinitely you can reduce risk of a data breach, and avoid the consequences of lost or stolen data.
Enhancing Data Accuracy
Reducing the volume of stored data can lead to better data accuracy. Outdated or irrelevant information can introduce errors into datasets, which may impact decisions and processes reliant on this data.
Improving Efficiency
By reducing the volume of personal data that you have you will make it easier and quicker to find the data you need. It can also save money because there are costs associated with both storing data, and processing data.
The Obligations Imposed by Storage Limitation
The GDPR imposes specific obligations on data controllers and processors regarding the application of the storage limitation principle. The technical and organisational measures that need to be put in place are not difficult to do, but they are important for GDPR compliance.
Determining Retention Periods
Organisations must establish and document the retention periods for different categories of personal data. These retention periods must be reasonable and aligned with the data’s intended purpose.
Your retention periods should be set out in a clear retention policy.
For example, some employment information will need to be retained for decades if it relates to pensions. Alternatively some data, like sickness absence, may only be needed for a short while – perhaps a year.
It is worth noting retention periods are a minimum not a maximum. If you decide to keep some data items for longer than the retention period you need to be clear why.
Sign Up Here:
Regularly reviewing and deleting data that surpasses its retention period is important. This ensures that data is not stored indefinitely and is promptly disposed of when it is no longer necessary. Then of course the data need to be deleted. Hard copy information should be shredded or disposed of through confidential waste disposal. Electronic data should be thoroughly deleted and it should not be accessible via backups or in a “deleted items” folder. For organisations and individuals navigating data protection regulations, following best practices is vital: Maintaining a comprehensive inventory of the personal data you collect and store is the first step in adhering to storage limitation. This inventory should include details such as the data’s source, purpose, and retention period. This inventory is known as a Record of Processing Activity (ROPA) and is one of the requirements of data protection law. Develop secure systems for data erasure that has reached the end of its retention period. This includes digital data, physical records, and ensuring that no residual copies exist. Be prepared to respond to data subject requests regarding the deletion or modification of their personal data. Implementing efficient processes to address such requests is crucial. There are two key rights to be aware of when it comes to the principle of storage limitation: Right of Access: when people make subject access requests you must tell them what personal data you have, what you use it for, and who you have shared it with (among other things). It is therefore important to know what data you have and what data has been deleted. Right of Erasure: this is also known as “the right to be forgotten”. It means in some circumstances people can ask for the deletion of their personal data. This is not an absolute right and will only apply where you do not need to keep the data for your own business. Plus six months’ free post course support to help you apply your learning Rated 4.8 out of 5 on Trustpilot The fifth data protection principle, storage limitation, is an integral component of the GDPR’s framework. Understanding and applying this principle is not just a legal requirement; it is an ethical obligation that helps safeguard individual privacy, enhance data accuracy, and mitigate data-related risks. By adopting best practices for data storage and following legal requirements, organisations and individuals can ensure that personal data is retained only for as long as necessary, promoting responsible and respectful data management.Periodic Review and Deletion

Storage Limitation Best Practices
Record of Processing Activity
Secure Data Disposal
Data Subject Rights
Learn More About the GDPR
This GDPR training course includes the following modules:

Conclusion: Key Takeaways on Storage Limitation
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: